# Mailbuttons Mcp Server

> Governed email for AI agents over MCP — sandbox inboxes, server-side policy gate, tamper-evident audit. Registry: com.mailbuttons/mcp-server

- **Type:** MCP server
- **Install:** `agentstack add mcp-mailbuttons-mcp-server`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [mailbuttons](https://agentstack.voostack.com/s/mailbuttons)
- **Installs:** 0
- **Category:** [Communication](https://agentstack.voostack.com/c/communication)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [mailbuttons](https://github.com/mailbuttons)
- **Source:** https://github.com/mailbuttons/mcp-server

## Install

```sh
agentstack add mcp-mailbuttons-mcp-server
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# Mailbuttons MCP server

Governed email for AI agents, over the [Model Context Protocol](https://modelcontextprotocol.io).
Give an agent a scoped mailbox where **the server enforces the guardrails, not
the prompt**: sandbox-by-default inboxes, a policy gate on every send, and a
tamper-evident audit log. External sending and scope changes are human-approved,
never granted by the agent itself.

- Registry: [`com.mailbuttons/mcp-server`](https://registry.modelcontextprotocol.io/v0/servers?search=com.mailbuttons)
- npm: [`@mailbuttons/mcp-server`](https://www.npmjs.com/package/@mailbuttons/mcp-server)
- Platform: **[mailbuttons.com](https://mailbuttons.com)** · agent front door: **[mbag.ai](https://mbag.ai)**

## Use it

**Hosted (recommended)** — a streamable-HTTP endpoint served by the platform:

```
https://mailbuttons.com/api/v1/mcp/rpc
Authorization: Bearer    # mb_sandbox_... (or mb_prod_...)
```

**Local (stdio)** — run the npm package and let your agent launch it:

```jsonc
{
  "mcpServers": {
    "mailbuttons": {
      "command": "npx",
      "args": ["-y", "@mailbuttons/mcp-server"],
      "env": { "MAILBUTTONS_API_KEY": "mb_sandbox_..." }
    }
  }
}
```

Get a scoped token from the dashboard or `POST /api/v1/mcp/sandbox-inboxes`.
Sandbox tokens can never send externally until a human promotes them.

## What the server enforces

- **Inbound** — a per-mailbox sender policy, fail-closed: mail from strangers
  bounces by default, so nobody can prompt-inject your agent just by emailing it.
- **Outbound** — a recipient blocklist the agent can read but not change; a
  blocked send returns a normal `{"status":"blocked"}` result, not an error.
- **Caps + audit** — per-account send caps and a hash-chained audit log that
  records refusals too.
- **Escalation** — sending externally or widening scope is propose-only; a
  named human approves. The agent cannot approve its own request.

## Install as an agent skill

This repo ships a root `SKILL.md`, so any skills-aware agent can add it:

```bash
npx skills add mailbuttons/mcp-server
```

## Docs

- Agent signup (for agents): https://mbag.ai/docs/agent-signup.md
- Trust model: https://mbag.ai/docs/trust-model.md
- OpenAPI: https://mbag.ai/api/openapi.json
- Framework recipes: [`references/`](./references) (Claude Agent SDK, LangChain, plain SDK)

Mailbuttons is a trading name of Code Cutter Limited (UK, no. 08453060). MIT licensed.

## Source & license

This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [mailbuttons](https://github.com/mailbuttons)
- **Source:** [mailbuttons/mcp-server](https://github.com/mailbuttons/mcp-server)
- **License:** MIT

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/mcp-mailbuttons-mcp-server
- Seller: https://agentstack.voostack.com/s/mailbuttons
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
